PT-2007-2927 · Microsoft+1 · Windows+1

Published

2007-03-20

·

Updated

2024-08-07

·

CVE-2007-1538

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions McAfee VirusScan Enterprise version 8.5.0.i
Description The software uses insecure permissions for certain Windows Registry keys, allowing local users to bypass local password protection via the UIP value in "HKEY LOCAL MACHINESOFTWAREMcAfeeDesktopProtection" or "HKEY LOCAL MACHINESOFTWARENetwork AssociatesTVDVirusScan EntrepriseCurrentVersion". However, this issue has been disputed by third-party researchers, who claim that the default permissions for HKEY LOCAL MACHINESOFTWARE do not allow for write access and the product does not modify the inherited permissions, suggesting a possible interaction error with another product.
Recommendations For McAfee VirusScan Enterprise version 8.5.0.i, consider restricting access to the vulnerable Windows Registry keys as a temporary workaround until a patch is available. Additionally, review the product's configuration and permissions to ensure they are set correctly to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2007-1538

Affected Products

Mcafee Virusscan Enterprise
Windows